Story thread · 3 reports / 3 sources

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

thehackernews.com · 1d

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

First report: Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data darkreading.com, 4d

The coverage

  1. Passkey-themed phishing attacks lead to Microsoft 365 data theft

    bleepingcomputer.com · 3d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.